Air Force Pair Jailed for $2M BEC Scam

The Record · Medium sophistication
Last updated September 30, 2026

Two U.S. Air Force members were sentenced to prison for running a business email compromise (BEC) scheme that stole more than $2 million. They phished businesses to steal email logins, then took over real email threads and sent "updated" wiring instructions to redirect large payments into accounts they controlled.

How the attack worked

This case involved two U.S. Air Force members who ran a business email compromise scheme that stole more than $2 million from at least 15 organizations. The scheme began with phishing emails sent to businesses in order to steal login credentials for employee email accounts. Once inside a mailbox, the attackers did not act immediately. Instead, they watched for discussions of payments, waiting for the right moment to intervene in an active transaction.

When a payment conversation appeared, the attackers inserted themselves into the existing email chain and sent "updated" wiring information, using the stolen credentials and spoofed email addresses to make the request appear to come from a trusted business partner. Prosecutors cited diverted payments including a $1.7 million wire and a $720,000 wire as part of the scheme. Stolen financial data, including account numbers and card information, was also used for purchases or sold to other criminals.

Why it succeeded

The scheme worked because it exploited trust that already existed inside real conversations rather than trying to create trust from scratch. Key factors included:

  • Compromised or spoofed email addresses that appeared to belong to a known vendor or business partner
  • Requests embedded inside an active, ongoing invoice or payment thread rather than sent as a new, suspicious email
  • Timing tied to real payment discussions the attackers were monitoring inside breached mailboxes

Because the fraudulent request arrived as a continuation of a legitimate exchange, it bypassed the natural skepticism people apply to unexpected or out-of-context messages.

What to watch for

Finance, accounts payable, accounting, procurement and executive staff handling payments should treat these signals as red flags:

  • Bank or wiring details that change mid-transaction, especially late in a payment process
  • A sender address that looks correct but may be spoofed or come from a compromised mailbox
  • Wiring changes introduced inside an existing thread instead of through a separate, verified channel

How to build resistance

Organizations can reduce exposure to this pattern with a few concrete steps:

  • Treat any change to wiring instructions as high risk and verify it using a trusted, out-of-band method such as a known phone number or vendor portal, even if the request appears inside a familiar email thread
  • Train staff to recognize and report credential-harvesting phishing attempts, since stolen logins are what make these impersonations convincing
  • Limit who is authorized to change payment instructions and require additional approval for high-dollar transfers, since attackers may be monitoring mailboxes for the right moment to strike

These practices address the specific mechanics seen in this case: credential theft, email thread hijacking, and mid-transaction payment redirection.

Key findings

  • Attackers sent phishing emails to businesses to steal employee email account credentials.
  • They used stolen credentials and spoofed email addresses to take over email chains and redirect legitimate payments.
  • They monitored inboxes for payment conversations and inserted themselves into existing threads with "updated" wiring information.
  • At least 15 organizations were targeted; prosecutors cited diverted payments including $1.7M and $720K wires.
  • Stolen financial data (account numbers, credit/debit card info) was used for purchases or sold to other criminals.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounts Payable, Accounting, Procurement/Vendor Management, Executive assistants involved in payments.
  • Affected industries: Multiple industries (various victim organizations).
  • Attack channels: email.
  • Impersonated: A known business partner/vendor (using a compromised or spoofed email identity).

Red flags to watch for

  • Bank/wiring details change during an active invoice/payment conversation
  • Sender address may be spoofed or coming from a compromised mailbox while appearing to be a trusted partner
  • Request is embedded inside an existing email thread to look legitimate
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the attackers steal money without hacking bank accounts?

They phished businesses to steal employee email credentials, then used those logins and spoofed addresses to take over existing email threads and insert fake wiring instructions into legitimate payment conversations.

What made this business email compromise scheme effective?

The attackers monitored compromised inboxes for payment discussions and inserted themselves into ongoing threads with updated wiring details, making the fraudulent request look like a natural continuation of a trusted conversation.

How can organizations defend against this kind of wire fraud?

Treat any change to wiring instructions as high risk and verify it through a trusted, out-of-band channel such as a known phone number, and limit who is authorized to approve changes to payment details.

Who is most at risk from this type of attack?

Finance, accounts payable, accounting, procurement, and executive assistants who handle payments are the primary targets since they are the ones acting on wiring instructions.

Read the video transcript

Two Air Force members just got jailed for a $2 million scam that started with one innocent-looking email. They phished employee logins, sat inside real inboxes, watched payment threads, then replied in the same email chain: 'Hi, please use the updated wiring information for this payment going forward.' Here’s the trap: the email comes from the real thread, the real name, the real invoice details, only the bank account is swapped, sending money to them instead of your vendor. If wiring details ever change mid-email thread, stop. Call the vendor on a known phone number you already trust and confirm before you move a cent.

Similar attacks

Microsoft Disrupts ‘EvilTokens’ Phishing Service

Microsoft Disrupts ‘EvilTokens’ Phishing Service

Microsoft says it disrupted the “EvilTokens” phishing-as-a-service platform, which it links to compromises of over 12,000 inboxes across more than 10,000 organizations. The service used AI to tailor phishing emails to a victim’s role and to analyze compromised inboxes to identify trusted…

September 23, 2026
Hackers Could Weaponize Email AI to Impersonate CEOs

Hackers Could Weaponize Email AI to Impersonate CEOs

Barracuda researchers simulated how an attacker who already compromised one employee mailbox could use the account’s built-in email AI assistant to hide evidence, learn org context, and draft convincing internal phishing emails. In their proof of concept, the attacker used an invoice-themed link to…

August 4, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
EvilTokens Used AI to Supercharge Phishing Scams

EvilTokens Used AI to Supercharge Phishing Scams

Microsoft and UK police took down “EvilTokens,” an AI-powered phishing service sold on Telegram that helped criminals compromise email accounts and then rapidly find the best ways to commit fraud. The service could analyze a victim’s inbox to identify trusted relationships and financial workflows,…

September 22, 2026
FBI Warns of OAuth Consent Phishing Tricks

FBI Warns of OAuth Consent Phishing Tricks

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters…

September 11, 2026
Fake IT Calls Steal Microsoft 365 Access

Fake IT Calls Steal Microsoft 365 Access

Microsoft reports a real-world campaign where attackers call or text employees’ personal phones while posing as internal IT. Victims are pushed to “update” passkeys/MFA/SSO and click a link to a fake Microsoft sign-in page, letting attackers get into Microsoft 365 and quietly pull email and files…

September 10, 2026